Architecture: Bitwarden (central vault) → rbw CLI → gnome-keyring (local cache via org.freedesktop.secrets D-Bus). All apps (himalaya, git, ssh-agent, JetBrains IDEs, browsers) now read secrets via libsecret/secret-tool through gnome-keyring. Changes: - Install gnome-keyring + rbw, enable as systemd user service - Configure rbw → bitwarden.jantec.xyz (ironmikechw+bitwarden@gmail.com) - Migrate 45 meaningful entries from KWallet → BW + GK - Switch git credential.helper from store to libsecret - Document: one-pager, ADR, migration checklist, NEXT_STEPS update - Skill: devops/secrets-migration for reuse Post-reboot manual: himalaya IMAP passwords (4 accounts, were not in KWallet) and GitHub CLI token re-auth. See docs/product/passwords.md for the full guide.
1.6 KiB
1.6 KiB
AGENTS.md (mw-pfeddersheim-workstation)
Project Overview
This repository manages the infrastructure, configuration, and maintenance for Michael Wegener's primary workstation at satware AG (Pfeddersheim location). It uses Ansible for system configuration and shell scripts for maintenance.
Key Directories
ansible/: Configuration-as-Code via Ansible roles and playbooks.docs/: PARA-structured documentation (Product, ADR, Learnings, Tech).scripts/: Automation and maintenance scripts.config/: Templates for system configuration files.
Essential Commands
| Task | Command |
|---|---|
| Apply Configuration | ansible-playbook ansible/workstation.yml |
| System Maintenance | bash scripts/maintenance.sh |
| Verify Ansible | ansible-playbook ansible/workstation.yml --check |
Standards
- Baby Steps™: Small, verifiable changes (<200 LOC per commit).
- PARA Documentation: Keep documentation updated in the
docs/folder. - Zero-Trust: Secrets must be handled via Ansible Vault or environment variables.
Guardrails
- NEVER commit raw secrets to the repository.
- ALWAYS run Ansible with
--checkbefore applying changes. - NEVER modify system configuration directly if it can be managed via Ansible.
- Secrets Management: All secrets stored in Bitwarden (
bitwarden.jantec.xyz) and cached locally ingnome-keyring(D-Bus secrets service). Seedocs/product/passwords.mdfor details.
Rules Hierarchy
- Global rules:
Rules/ - Project rules:
.clinerules/ - Agent instructions:
AGENTS.md(this file)